Reverse Engineering a Government Certification System2025-02-26 19:00:00|CybersecurityReverse EngineeringWeb Security

2025-02-28
KBS
SecurityWeb DevelopmentLinuxNetworkingAI/ML
Reverse Engineering a Government Certification System2025-02-26 19:00:00|CybersecurityReverse EngineeringWeb Security

Today, I had a training session at work which required me to leave fairly early in the morning. As part of this work related training, we were required to complete some online computer modules which we were given links to ahead of time. With hopes of being allowed to leave early, I decided to stay awake and complete the online modules beforehand. One of these was the Ontario Ministry of Labour’s 4-step safety awareness module, which issues a certificate upon completion and is absolutely mandatory via company policy to work each year.

While working through it, a particular statement caught my attention:*“Your results are not stored.”*This immediately signaled that there was no backend database tracking progress—meaning everything had to be generated dynamically when the course was completed.

Why This Matters

This isn’t just about exploiting a poorly designed certificate system—it’s about understandinghow input validation, authentication, and server-side security should be implemented. A government-issued certification process that doesn’t validate completion on the server side opens up the potential for fraud. If certificates can be generated with any name, there’s no way for an employer to verify authenticity.

But lets be clear - by generating a certificate and avoiding the course, one is doing an injustice to themselves. Falsifying it, while absolutely in no way (in this case) could be proved, this particular course is designed to let you know what your rights are as a worked. It simply served as an example of how input validation is critical and can be abused.

Lessons Learned

  • Always validate dataon the server, not just in the client’s browser.
  • Never trust user input blindly—especially when issuing official documents.
  • Implement some form of authentication or tracking mechanism to ensure certificates are only generated for users who have legitimately completed the course.

Until then,the system remains a playground for anyone with a basic understanding of encoding and API requests.

**Disclaimer:**This article is purely for educational purposes. Manipulating government systems without authorization is illegal. This discusses manipulation of a public services output by sending it manipulated input, where no data is being stored to a database, no dangerous queries are causing damage or displaying sensitive data.